Announcement

Collapse
No announcement yet.

mec 16xx dump with info block

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #41
    Re: mec 16xx dump with info block

    They procedure and the way I see things work:
    1. READ ec/kbc, now you have a backup of original firmware.
    2. Before you PROGRAM ec/kbc you have to ERASE it, is at this specific step where the firmware is erased, which also causes protected eeprom area to be erased thus eliminating Supervisor Password, CompuTrace configuration, etc.
    3. PROGRAM original firmware.
    4. All is left to do is to use Lenovo UEFI Maintenance Utility to program Model Number, Serial Number and other data. (Some of needed data can be recovered from laptop stickers affixed to motherboard, other option is to take a picture of BIOS welcome screen before initiating procedure).


    @-Yevhen-
    Make sure you ERASE before you PROGRAM ec/kbc, other possibility is that you haven’t disconnected all source of energy (including CMOS battery) after you do the ERASE/PROGRAM, so the ec/KBC may still be keeping the contents (password, computrace configuration, etc.) in its internal volatile memory.
    Last edited by AAAC; 05-25-2021, 09:29 AM.

    Comment


      #42
      Re: mec 16xx dump with info block

      Originally posted by RethoricalCheese View Post
      I just moved reset signal resistor and used keyboard connector to do all the programming. Worked well.
      Did u program T490 via keyboard connector ?? not via jtag pads ?

      Comment


        #43
        Re: mec 16xx dump with info block

        For my T490s nm-b891 this method does not work. My actions:
        1) disconnected all source of energy
        2) read and saved main bios 32mb and 256kb MEC1663
        3) erase end check blank main bios and MEC
        4) programmed MEC1663, dump from bios update (clear EC dump)
        5) programmed main bios, dump from bios update (clear bios regin + clear me region)
        6) turn on, and.... SVP remains active.


        I think SVP in this platform duplicated in 3 places - Main Bios, Embeded controller(MEC1663) and TPM (ST33HTPH)...
        Do you have any ideas to check the flash / ROM TPM module?

        Comment


          #44
          Re: mec 16xx dump with info block

          Originally posted by RethoricalCheese View Post
          Got my problem solved. Used RT809H now instead of SAS JIG.

          Edit:

          Now, to write back data, it seems I need U1 tool. The old maintenance disk threw an error about locked eeprom.
          U1 update tool throws a "download error".

          Can anybody make and upload ISO of that tool?

          Hi! Can u plz help me? I'm trying to read MEC1663 from a T590 and used the pinnout posted earlier...moved the 10k resistor and i always get MEC Chip ID: 0xFFFFFFFF
          042: ID verification error.
          I'm using a RT809H

          Thanks

          Comment


            #45
            Re: mec 16xx dump with info block

            Hi guys. Still no luck with the MEC1663 from the T590 NM-B901 board. I am using a RT809H on the JTAG but there must be something that i'm doing wrong. I've tried the pinnout from post #31, moved the resistor but i always get Chip ID error.

            I assume that the CLK signal goes to TCK pin on the RT809H..or?
            Anyone that managed to read the MEC with RT809H programmer to explain the steps?
            Any help or ideea is apreciated.

            Thank you!

            Comment


              #46
              Re: mec 16xx dump with info block

              this is the pin to connect to the programmer
              Attached Files

              Comment


                #47
                Re: mec 16xx dump with info block

                @syladrian
                Have you added the 10k PULL-UP resistors to the JTAG lines? Check a ThinkPad schematic EC/KBC JTAG interface.

                Comment


                  #48
                  Re: mec 16xx dump with info block

                  @syladrian
                  select MEC1653 from RT809H List, connect the charger and read the chip it should be 290kb.
                  Erase the chip and write the File back
                  (done 2days ago)

                  Comment


                    #49
                    Re: mec 16xx dump with info block

                    Work for svp password. But for computrace cant be done. Computrace still remaining when entering bios setup. All id are gone, but computrace still actived. Any solution?

                    Comment


                      #50
                      Re: mec 16xx dump with info block

                      Software version 1.1.1.6 date 13.06.2021
                      Running Microsoft Windows 7 Professional 64 bit
                      Intel(R) Core(TM) i5-3320M CPU @ 2.60GHz
                      .NET Framework Version: 4.7
                      Device connected in work mode
                      Firmware version 1.0.7.3 date 1.6.2021
                      MEC mode selected
                      MEC IDCODE: B1240020
                      Device ID: 27
                      Device Revision: 1
                      Device Status: C
                      Flash Status: 000300000C
                      Boot Block in not protected mode
                      Flash Configuration: 010000000C
                      File size : 262144 byte
                      Start erase in: 2021-06-21 09:06:49
                      End erase in: 2021-06-21 09:06:50
                      Erase OK
                      Start blank check: 2021-06-21 09:06:50
                      End blank check in: 2021-06-21 09:06:54
                      Blank Check OK
                      File size : 262144
                      Flash size :262144
                      Start writing: 2021-06-21 09:06:54
                      End writing in: 2021-06-21 09:06:57
                      Write OK
                      File size : 262144
                      Flash size :262144
                      Start verify: 2021-06-21 09:06:57
                      error
                      address:30000
                      buffer: 2 device: FF
                      Verify false


                      Software version 1.1.1.6 date 13.06.2021
                      Running Microsoft Windows 7 Professional 64 bit
                      Intel(R) Core(TM) i5-3320M CPU @ 2.60GHz
                      .NET Framework Version: 4.7
                      Device connected in work mode
                      Firmware version 1.0.7.3 date 1.6.2021
                      MEC mode selected
                      MEC IDCODE: B1240020
                      Device ID: 27
                      Device Revision: 1
                      Device Status: C
                      Flash Status: 000100000C
                      Boot Block in not protected mode
                      Flash Configuration: 010000000C
                      File size : 262144 byte
                      Start erase in: 2021-06-21 09:18:17
                      End erase in: 2021-06-21 09:18:18
                      Erase OK
                      Start blank check: 2021-06-21 09:18:18
                      End blank check in: 2021-06-21 09:18:21
                      Blank Check OK
                      File size : 262144
                      Flash size :262144
                      Start writing: 2021-06-21 09:18:21
                      End writing in: 2021-06-21 09:18:24
                      Write OK
                      File size : 262144
                      Flash size :262144
                      Start verify: 2021-06-21 09:18:24
                      error
                      address:30000
                      buffer: 2 device: FF
                      Verify false
                      SVODE 3 still save only 192 KB. Not 256 KB. So motherboard still is dead.

                      Some one have idea for this ?? Or i need reapleace this MEC and try again ??

                      Comment


                        #51
                        Re: mec 16xx dump with info block

                        Originally posted by LenBios View Post
                        @syladrian
                        select MEC1653 from RT809H List, connect the charger and read the chip it should be 290kb.
                        Erase the chip and write the File back
                        (done 2days ago)
                        @syladrian
                        select MEC1653 from RT809H List, connect the charger and read the chip it should be 290kb.
                        Erase the chip and write the File back
                        (done 2days ago)

                        Hi,
                        i have used rt809 1653 chip but ID identification error. I have used #33 schema T490 with resistor attached. Can you please share more details or picture how to connect? Power supply only from programmer.
                        Many thanks.

                        Comment


                          #52
                          Re: mec 16xx dump with info block

                          Hi all,
                          thanks to LenBios I have read MEC dump via RT809H 1653 #ISP settings 290kB dump. Power on.
                          I have erased the chip and then waited, reconnect and load back the same file but after this step KBC looks dead does not boot at all.
                          Any idea what to do now? vent is not working, power diode is not working now.

                          Thanks.

                          Comment


                            #53
                            Re: mec 16xx dump with info block

                            Issue sorted. MEC reflashed.

                            Comment


                              #54
                              Re: mec 16xx dump with info block

                              Someone have pinout and photo from resistor move to enable jtag in this carbon ?? X1 Carbon 7th
                              Attached Files

                              Comment


                                #55
                                Re: mec 16xx dump with info block

                                Good afternoon. I was able to delete the password via JTAG on T490. But I had to solder the wires. Can I do it through the keyboard connector?

                                Comment


                                  #56
                                  Re: mec 16xx dump with info block

                                  Originally posted by RethoricalCheese View Post
                                  The resistor in my last picture was indeed correct. I can read/write MEC now.

                                  The problem is, looks like my SAS JIG (which doesnt have MEC1663 in support list) is not able to clear the write-only area for some reason. What programmer should be used?



                                  Now stuck with the same issue again


                                  Using SVOD3 this time on a T490s. Read, verify, erase, verify blank, write (erase, verify blank, write, verify) all passed but DMI and password still there. It doesn't seem to clear the write-only area. Tried waiting without power between erasing and writing.

                                  Even tried clearing uefi region just in case it copies backup from there. (ME is original tho).


                                  Out of ideas.

                                  Comment


                                    #57
                                    Re: mec 16xx dump with info block

                                    Originally posted by RethoricalCheese View Post
                                    Now stuck with the same issue again


                                    Using SVOD3 this time on a T490s. Read, verify, erase, verify blank, write (erase, verify blank, write, verify) all passed but DMI and password still there. It doesn't seem to clear the write-only area. Tried waiting without power between erasing and writing.

                                    Even tried clearing uefi region just in case it copies backup from there. (ME is original tho).


                                    Out of ideas.
                                    use RT809H works always

                                    Comment


                                      #58
                                      Re: mec 16xx dump with info block

                                      Yup, last time I did this, RT809H worked fine. But that was a loaner. I was told SVOD3 is even better so that's what got bought instead

                                      And yes, you can use keyboard connector on T490. But disassembly is still required to move the JTAG reset resistor.

                                      Comment


                                        #59
                                        Re: mec 16xx dump with info block

                                        Originally posted by RethoricalCheese View Post
                                        Yup, last time I did this, RT809H worked fine. But that was a loaner. I was told SVOD3 is even better so that's what got bought instead

                                        And yes, you can use keyboard connector on T490. But disassembly is still required to move the JTAG reset resistor.
                                        use such pins its easy to use, no need to solder the wires on JTAG Points
                                        Last edited by LenBios; 07-22-2021, 11:03 PM.

                                        Comment


                                          #60
                                          Re: mec 16xx dump with info block

                                          this pins
                                          Attached Files

                                          Comment

                                          Working...
                                          X